Chapter 9: Autopsy
Autopsy and The Sleuth Kit, both created by Brian Carrier, go hand in hand. The Sleuth Kit is a powerful suite of CLI forensic tools, whereas Autopsy is the GUI that sits on top of The Sleuth Kit and is accessed through a web browser. The Sleuth Kit supports disk image file types including RAW (DD), EnCase (.01), and the Advanced Forensic Format (AFF).
The topics that we will cover in this chapter include the following:
- Introduction to Autopsy
- The sample image file used in Autopsy
- Digital forensics with Autopsy